1. Parties and precedence
The customer named in the order is the controller, or a processor authorised by its own controller. The applicable Scly provider named in that order is its processor or subprocessor for instructed workspace processing. This DPA is a draft requiring an executed agreement; a page view is not execution. The provider’s independent account administration is covered by the Privacy Policy. This DPA governs processing conflicts with commercial terms.
2. Processing schedule
Subject matter: assisting the customer’s ecommerce content and workflow operations. Duration: the service period and the agreed return/deletion phase. Nature: receiving, storing, organising, analysing, generating, rendering and transmitting approved content to enabled services and destinations.
Purposes: the customer’s requested product research, page creation, teaching, creatives and task planning. Data categories: merchant contact details and any personal data in submitted prompts, product information, reviews, images, video, voices, source records and outputs. Data subjects may include authorised users, creators, reviewers and people appearing in customer-supplied media. Special-category data, children’s data, raw customer lists and sensitive identifiers are outside the proposed scope unless specifically agreed with additional safeguards.
3. Instructions, confidentiality and security
Process personal data only on the customer’s documented instructions, including any international transfer, unless applicable law requires otherwise. Inform the customer of a legal processing requirement where permitted. Notify the customer if an instruction appears to infringe applicable data-protection law. Authorised personnel must have confidentiality duties and access limited to the necessary purpose.
Maintain risk-appropriate technical and organisational safeguards. The security schedule must describe deployed controls, not intended controls. The audited pilot has password hashing, signed sessions, tenant scoping and encrypted store credentials; production hosting, MFA for staff, backup restoration, retention and incident drills remain deployment requirements.
4. Subprocessors and transfers
Obtain the customer’s written specific or general authorisation before appointing subprocessors. Proposed general-authorisation procedure: maintain a register, provide 30 days’ advance notice of a new or replacement subprocessor where practicable, allow a reasoned objection and resolve it or provide an exit from the affected processing. No draft register grants authorisation.
Bind subprocessors to equivalent data-protection obligations and remain responsible for their performance under this DPA. The schedule must identify the actual legal provider, location, function, data and transfer safeguard. Restricted transfers require a valid mechanism and necessary assessment. Standard contractual clauses are not deemed signed merely because this document mentions them.
5. Assistance and incidents
Assist the customer with data-subject requests, security duties, impact assessments and regulatory consultations, taking into account the nature of processing and available information. Do not decide on the merchant’s customers’ rights independently unless legally required.
Notify the customer without undue delay after becoming aware of a personal-data breach affecting instructed data. Share known facts, categories and approximate numbers affected, likely consequences, mitigation and a contact, with staged updates where needed. Preserve an incident record. A processor notification does not replace the controller’s regulatory or individual notifications.
6. Return, deletion and audit
At the customer’s choice, return or delete instructed personal data at the end of services and delete remaining copies unless law requires retention. Agree an enforceable completion period and a bounded backup expiry before production. Explain any legal retention, restrict further use, and ensure deleted data is not reintroduced during backup restoration.
Make information demonstrating compliance available and allow reasonable audits and inspections by the customer or its authorised auditor, subject to proportionate confidentiality and security safeguards that do not frustrate the audit right. Document findings and corrective actions. Liability arrangements must not restrict data subjects’ statutory rights.
7. Schedules awaiting completion
Before execution, complete: customer and provider details; authorised instructions; security measures; actual hosting and access locations; approved subprocessors; transfer mechanisms; retention and backup expiry; deletion completion period; incident contacts; and the authorised signatories.